Release date:
Updated on:
Affected Systems:
OwnCloud 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56658
OwnCloud is a solution for source file synchronization and sharing.
Versions earlier than ownCloud 4.5.2/lib/filesystem. PHP files have the Upload Vulnerability. Remote attackers who pass authentication can exploit this vulnerability to upload a special file, bypass the application blacklist check, and execute arbitrary code.
<* Source: Shai rod
Felix Richter
Link: http://secunia.com/advisories/51357/
Http://owncloud.org/security/advisories/oC-SA-2012-005/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OwnCloud
--------
OwnCloud has released a Security Bulletin (oC-SA-2012-005) and patches for this:
OC-SA-2012-005: Code execution in/lib/filesystem. php (oC-SA-2012-005)
Link: http://owncloud.org/security/advisories/oC-SA-2012-005/